GHSA-f984-9xfw-9437MediumCVSS 6.5

A rogue webpage could override the injected WKUserScript used by the logins autofill, this...

Published
May 24, 2022
Last Modified
August 19, 2026

🔗 CVE IDs covered (1)

📋 Description

A rogue webpage could override the injected WKUserScript used by the logins autofill, this exploit could result in leaking a password for the current domain. This vulnerability affects Firefox for iOS < 28.

🔗 References (4)